The real problem is actually, not an architectural one. Security standards dictate that no device, no matter what its function, span 2 networks of differing security domains. This is an attempt to see if there was a way we could safely work around this.
The hosts on the network segment to be scanned are not considered hostile, but since they are in a lower security domain, we need to technically consider them hostile, to consider them as if they had been compromised. Other than ipchains\iptables firewalling, any other suggestions? -----Original Message----- From: Rob Nelson [mailto:[EMAIL PROTECTED]] Sent: Thursday, January 24, 2002 9:53 AM To: Perciaccante, Robert Subject: RE: Nessus on "blind" interface >The overall concept is this. Eth1 is used to collect results, change >.nessusrc files, etc. Eth0 is on a DMZ, and if bound to an IP address, is >vulnerable to attack from anyone on this segment. > >If Nessus was able to send packets out with spoofed IP/MAC addresses, and >then sniff the results off the wire, it could perform the necessary scans, >but not itself be vulnerable to attack on that segment. If you're worried about a host you're scanning attacking you, then even with IP/MAC spoofing, you'd still be vulnerable because they'd have to have some way to respond to your probes. The best you could do is possibly run each test after changing to a random unused IP address on the segment - run one test from 10.0.0.14, the next from 10.0.0.241, etc. But that's pretty complex for what you *should* do - ifup eth0, nessus probe the target, ifdown eth0. You're not going to become invulnerable from attack when you're scanning no matter what, you just mitigate who you're vulnerable to. The only other thing I can think of is to use something like ipchains or ipfilter to block all traffic except from the IP you're scanning...which requires re-applying rulesets between each host you scan. Pretty tedious. Rob Nelson [EMAIL PROTECTED]
